LastPass users are facing a dangerous new phishing campaign that is trying to steal their credentials. Cybercriminals pose as a popular password management company to trick users into believing they need to back up their digital vaults, where their passwords are stored, locally.. According to a statement released by LastPass, this campaign began on January 19 and was described as very compelling.
Don’t fall for this phishing scam
The scam emails appear to come from illegitimate addresses such as “support@lastpass(.)server8” and “support@sr22vegas(.)com” and are designed to create a sense of urgency by claiming that the backup is necessary due to scheduled maintenance. LastPass emphasized that it did not ask its customers to back up their accounts for 24 hours, warning of possible manipulation.
Hackers are clever by including a “Back Up Now” button that, when clicked, takes users to a phishing site designed to steal their credentials, possibly including their master password. This type of scam highlights the importance of being alert to warning signs and practicing good cyber habits..
Experts recommend that users use different services to store important passwords and remember the master password without leaving it written down in an accessible place. In addition, passkeys offer a more secure alternative because they are tied to a specific device and are harder to crack than traditional passwords..
In this context, it is very important to remain calm and not be carried away by urgency when receiving suspicious emails. It is always advisable to carefully check links and the legitimacy of email addresses to avoid fraud that could compromise the security of our personal information..


